It was discovered that libgsf incorrectly handled certain Compound Document
Binary files. If a user or automated system were tricked into opening
a specially crafted file, a remote attacker could possibly use this issue
to execute arbitrary code.
Category Archives: Advisories
libdigidocpp-4.0.0-1.fc41
FEDORA-2024-f474f99541
Packages in this update:
libdigidocpp-4.0.0-1.fc41
Update description:
Upstream release of libdigidocpp
libdigidocpp-4.0.0-1.fc40
FEDORA-2024-f7a5b49a73
Packages in this update:
libdigidocpp-4.0.0-1.fc40
Update description:
Upstream release of libdigidocpp
USN-7022-3: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
– GPU drivers;
– Modular ISDN driver;
– MMC subsystem;
– SCSI drivers;
– F2FS file system;
– GFS2 file system;
– Netfilter;
– RxRPC session sockets;
– Integrity Measurement Architecture(IMA) framework;
(CVE-2021-47188, CVE-2024-39494, CVE-2022-48791, CVE-2022-48863,
CVE-2024-42228, CVE-2024-38570, CVE-2024-42160, CVE-2024-26787,
CVE-2024-27012, CVE-2024-26677)
firefox-131.0.2-1.fc40
FEDORA-2024-db72f480e8
Packages in this update:
firefox-131.0.2-1.fc40
Update description:
New upstream version (131.0.2)
USN-7060-1: EDK II vulnerabilities
It was discovered that EDK II did not check the buffer length in XHCI,
which could lead to a stack overflow. A local attacker could potentially
use this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-0161)
Laszlo Ersek discovered that EDK II incorrectly handled recursion. A
remote attacker could possibly use this issue to cause EDK II to consume
resources, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2021-28210)
Satoshi Tanda discovered that EDK II incorrectly handled decompressing
certain images. A remote attacker could use this issue to cause EDK II to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2021-28211)
It was discovered that EDK II incorrectly decoded certain strings. A remote
attacker could use this issue to cause EDK II to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2021-38575)
It was discovered that EDK II had integer underflow vulnerability in
SmmEntryPoint, which could result in a buffer overflow. An attacker
could potentially use this issue to cause a denial of service.
(CVE-2021-38578)
Elison Niven discovered that OpenSSL, vendored in EDK II, incorrectly
handled the c_rehash script. A local attacker could possibly use this
issue to execute arbitrary commands when c_rehash is run. This issue
only affected Ubuntu 16.04 LTS. (CVE-2022-1292)
SEC Consult SA-20241009-0 :: Local Privilege Escalation via MSI installer in Palo Alto Networks GlobalProtect (CVE-2024-9473)
Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 09
<<< image/webp; name=”cmd.webp”: Unrecognized >>>
DSA-5788-1 firefox-esr – security update
Damien Schaeffer discovered a use-after-free in the Mozilla Firefox web
browser, which could result in the execution of arbitrary code.
firefox-131.0.2-1.fc39
FEDORA-2024-f109ae6fc7
Packages in this update:
firefox-131.0.2-1.fc39
Update description:
Updated to latest upstream (131.0.2)
firefox-131.0.2-1.fc41
FEDORA-2024-d85494e836
Packages in this update:
firefox-131.0.2-1.fc41
Update description:
Updated to latest upstream (131.0.2)